CVE-2019-3718

Description

Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.156

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-3718,CVE-2019-3719 are affected in Dell SupportAssist 3.2.0.89Windows
Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-3718)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234